Microsoft Digital Defense Report: Governments Now Most Impacted Sector, Facing 27% of Threat Activity

|
3 minutes

Government share of observed threat activity rose to 27% in 2026, up from 17% in 2025; Microsoft outlines five priorities to help governments contain harm and keep essential services running

Government agencies and services were the sector most impacted by cyber threats in 2026. They accounted for 27% of observed activity, up from 17% in 2025, according to this year’s Microsoft Digital Defense Report. Governments are also the most frequently targeted sector for nation-state activity.

Top 10 global sectors impacted by threat actors in 2026

They are attractive targets because they hold sensitive information and operate essential services. They also sit at the center of complex networks involving agencies, contractors, technology providers and critical infrastructure operators.

Key findings 

  • Phishing accounted for 23% of observed intrusions in 2026, up from 7% in 2025. The figures confirm that compromised identities remain a key entry point for attackers. 
  • 52.2% of intrusions involving valid accounts resulted in additional credential theft. This highlights how quickly attackers can expand beyond an initial foothold.
  • AI is compressing the window for action. Adversaries are moving faster. The time from a vulnerability’s discovery in the wild to active weaponization can be well below 24 hours. At the same time, the number of publicly disclosed software vulnerabilities (commonly tracked as CVEs) is projected to reach a record 72,000 in 2026. 
  • Attackers are staying hidden longer. Dwell time, the period between an attacker gaining access and being detected or stopped, increased this year across multiple sectors. Organizations responded faster once intrusions were identified, but early detection remains a challenge as attackers mimic legitimate activity. 

“AI is changing the physics of cybersecurity. Attacks now move at machine speed, and defense must too,” said Yannis Stathopoulos, Regional Technology Officer, Europe South, Microsoft. “Across the Adriatic, our role is not simply to help organizations respond to the next attack, but to help businesses and governments build resilience by design, with security embedded into every layer of their digital transformation. The organizations best positioned for the future won’t be those with the most data, the largest security teams or the most advanced tools, but those that truly understand their ecosystems.”

Yannis Stathopoulos, Regional Technology Officer, Europe South, Microsoft

Five priorities to strengthen government resilience

Microsoft stresses that public-private partnerships are more important than ever, both for securing critical government infrastructure and for developing policy and regulation for emerging technologies. As AI shortens the time available to act, governments should take five steps: 

  1. Prepare for a faster threat environment. Agree on roles, responsibilities and trusted relationships before an incident occurs, so governments can decide, coordinate and communicate quickly in a crisis. 
  2. Build security into the AI ecosystem. Treat AI security as part of national resilience and critical infrastructure protection, not a narrow technical issue, through secure-by-design practices, testing, supply chain protections, accountability and international cooperation. 
  3. Plan for incidents to spread. Criminals and nation-state actors increasingly use the same entry points, so response plans should cover suppliers and partners and rely on cross-border collaboration. 
  4. Enable timely, two-way information sharing between the public and private sectors. Agencies should send useful intelligence and warnings back to their partners, supported by legal protections for good-faith sharing and investment in shared threat detection. 
  5. Prepare essential services to operate through disruption. Identify the most critical services and what they depend on and run regular scenario exercises with public and private partners. 

About the Microsoft Digital Defense Report

The Microsoft Digital Defense Report examines the cyber threat landscape and how it is reshaping risk for organizations and governments. This year’s edition covers threat trends observed from July 2025 to June 2026. [Link to full report]

Top image: Microsoft Digital Defense Report 2026

English (United States)
Your Privacy Choices Opt-Out Icon Your Privacy Choices
Consumer Health Privacy Sitemap Contact Microsoft Privacy Manage cookies Terms of use Trademarks Safety & eco Recycling About our ads